PT-2011-1020 · Policykit+3 · Polkit+3

Neel Mehta

·

Publicado

2011-04-19

·

Atualizado

2012-12-19

·

CVE-2011-1485

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions polkit versions prior to 0.104-r1 policykit-1 versions prior to 0.104-r1
Description The issue affects the polkit package in Gentoo Linux and policykit-1 in Debian GNU/Linux, allowing local exploitation that may lead to breaches in confidentiality, integrity, and availability of protected information. A race condition in the pkexec utility and polkitd daemon in PolicyKit allows local users to gain privileges by executing a setuid program from pkexec, related to the use of the effective user ID instead of the real user ID.
Recommendations For polkit versions prior to 0.104-r1, update to version 0.104-r1 or later to resolve the issue. For policykit-1 versions prior to 0.104-r1, update to version 0.104-r1 or later to resolve the issue. As a temporary workaround, consider restricting access to the pkexec utility and polkitd daemon to minimize the risk of exploitation.

Exploit

Correção

Race Condition

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01460
BDU:2015-09652
CVE-2011-1485
DSA-2319-1
OPENSUSE-SU-2024:10436-1
RHSA-2011:0455
RHSA-2011_0455

Produtos afetados

Red Hat
Pkexec
Policykit-1
Polkit